Features StacksPricing About Contact
Sign in →
06 // Core Architecture • Backup & Disaster Recovery

Zero-risk offsite backups. Instant disaster recovery.

Stream encrypted, chunk-deduplicated snapshots of every database, application, and server configuration straight to your own S3 bucket. Powered by Restic, automated quiescing, and preflight verification drills—zero database locks, zero CLI toil.

Restic Deduplication Engine Application Quiescing (Zero Locks) Automated Scratch Drills Preflight Restore Guard
backup-engine // restic s3:https://s3.eu-central-1.wasabisys.com/rubuz-backups
Scheduled: Daily at 02:00 UTC
Total Data Protected
142.8 GB
Across 8 apps & 4 databases
S3 Bucket Storage Used
16.4 GB
88.5% Deduplication Savings
Last Snapshot State
Verified
Scratch drill passed in 14s
Restore Readyness
1-Click Safe
Preflight headroom checked
Snapshot IDScope / TargetTransferredQuiesce TimeVerificationActions
#snp-a9f82d01 (latest)Full Server (Postgres, Redis, Apps, Domains)+142 MB (deduped)1.8s (Zero locks)✓ Restorable
#snp-e73b18c4Full Server (Nightly Automated Cron)+86 MB (deduped)1.4s (Zero locks)✓ Restorable
#snp-3c220f19Pre-Upgrade Snapshot (Local & Remote)+18 MB (deduped)0.9s (Zero locks)✓ Restorable
01 // Architectural Comparison

Why traditional VPS backups fail. And how Rubuz solves it.

Taking automated backups sounds simple until uncoordinated scripts lock your checkout transactions, or an unverified restore crashes halfway through with no recovery path.

✕ Legacy Backup Scripts & Basic Panels

The Fragile Legacy Approach

  • ✕
    Full SQL Dumps Every Night: Every single run dumps the entire 50GB database again, eating hundreds of gigabytes of expensive S3 storage and network bandwidth.
  • ✕
    Table Locks & Site Freezes: Dumping busy production databases without transactional coordination locks tables and drops user requests during checkout windows.
  • ✕
    Unverified Backups ("Schrödinger's Backup"): The file size is greater than zero, so the script says "Success"—until you attempt to restore and find corrupted tables or missing metadata.
  • ✕
    Raw DB Only (Lost App Context): You recover the SQL file, but custom domains, reverse proxy rules, environment secrets, and volume permissions are lost forever.
Rubuz Engineering Standard
✓ Rubuz Restic & Quiescing Engine

True Disaster Recovery Architecture

  • ✓
    Content-Defined Chunk Deduplication: Powered by Restic. Only changed data blocks are encrypted and pushed. 30 daily snapshots use almost the same storage as 1 snapshot.
  • ✓
    Intelligent Application Quiescing: Recognizes Postgres, MariaDB, MySQL, Redis, and Mongo. Safely flushes buffers in seconds without locking incoming HTTP traffic.
  • ✓
    Automated Scratch Verification Drills: Every backup is automatically test-restored in an isolated scratch tree to guarantee the snapshot is 100% restorable before marking it good.
  • ✓
    Atomic 1-Click Server Recovery: Blueprints, custom domains, UID maps, port routes, and databases are restored together onto any fresh Linux server in minutes.
02 // The Four Pillars

Engineered for real-world resilience.

Four independent safeguards working together to ensure your data is always safe, compact, and immediately recoverable.

Pillar 01

Restic Content-Defined Deduplication

Instead of treating backups as massive opaque tarballs, Rubuz uses content-defined chunking. If a 10 GB database only changes by 20 MB during the day, only that 20 MB delta is encrypted and transferred.

Impact:
• 85% to 92% reduction in S3 object storage usage
• Fast nightly syncs completing in seconds, not hours
• Zero incremental repository chaining headaches
Pillar 02

Application Quiescing & Zero Write-Lock

Capturing a database live without synchronization leads to torn pages and unrecoverable tables. Rubuz detects stateful storage engines, freezes filesystem writes via transactional flushes for mere milliseconds, and takes the snapshot.

Supported Engines:
• PostgreSQL, TimescaleDB, pgvector
• MariaDB, MySQL, Percona Server
• Redis, Valkey, KeyDB, MongoDB, ClickHouse
Pillar 03

Automated Scratch Verification Drills

A backup that cannot be restored is worthless. Immediately after writing each snapshot, Rubuz performs an automated drill: restoring artifacts into an isolated scratch tree to verify blueprint schemas, credentials, and SQL dump integrity.

Verified Artifacts:
• rubuz-metadata.json application schema validation
• Database dump headers and integrity checksums
• Blueprints, custom domains, and TLS secret mappings
Pillar 04

Preflight Headroom Guard & Atomic Restore

Before halting any production container during a restore, Rubuz runs a read-only preflight check. It verifies that disk headroom is at least 2× restore size for safe stage-and-swap, eliminating the risk of bricked servers.

Safety Guarantees:
• Read-only dry-run before touching live containers
• Disk headroom factor verification (avoids ENOSPC crashes)
• Zero ghost-container conflicts on post-restore rebuild
03 // Storage Sovereignty

Connect any S3-compatible cloud storage.

Your data belongs to you. Rubuz streams snapshots directly from your server to your chosen storage provider over TLS. We never store, inspect, or intermediate your backup payloads.

Amazon S3 Amazon S3 Global AWS
Cloudflare R2 Cloudflare R2 Zero Egress
Wasabi Cloud Wasabi Cloud Hot Storage
Backblaze B2 Backblaze B2 High Value
DO Spaces DO Spaces Simple S3
S3
MinIO / Custom Self-Hosted
🔒
Customer S3 Security Boundary: Credentials are encrypted in your database. Backups stream directly between your host and your bucket over TLS.
Zero Vendor Lock-In
04 // Frequently Asked Questions

Everything you need to know about Rubuz Backups.

Do backups lock my live database transactions during operation? ↓

No. Rubuz uses transaction-safe quiescing. Web tiers and HTTP traffic continue serving requests uninterrupted. Storage engines like PostgreSQL and MariaDB flush dirty buffers in a fraction of a second, avoiding global table read-locks that freeze shopping carts or API transactions.

Can I restore an entire server to a completely new VPS provider? ↓

Yes! Disaster recovery is provider-agnostic. Each Rubuz snapshot packages application metadata (rubuz-metadata.json), environment secrets, custom domain routing, and volume state. You can connect a fresh Hetzner, Vultr, or DigitalOcean server and restore your entire fleet with a single click.

How much bandwidth and storage does Restic deduplication save? ↓

Typically between 80% to 92%. Unlike traditional full dumps that upload entire databases repeatedly, Restic breaks data into variable-size content-defined chunks. Subsequent backups only transmit unique modified chunks, saving immense bandwidth and slashing S3 storage invoices.

Does Rubuz have access to my S3 encryption keys or backup files? ↓

Never. Your customer S3 bucket is the ultimate security boundary. Snapshot payloads are transferred directly from your VPS to your cloud storage endpoint over TLS. Rubuz control plane orchestrates jobs but never touches or stores your data payloads.

Ready for True Disaster Recovery

Never lose a byte of data. Deploy with confidence.

Connect any Linux VPS in 60 seconds. Enjoy automated S3 backups, one-click restores, and zero CLI maintenance starting today.

✓ No credit card required • Connect unlimited apps • 14-day trial